SonicWall SMA1000 zero-days used to install custom malware on VPN
Source headline: SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Intelligence Summary
SonicWall SMA1000 appliances have been targeted using two vulnerabilities that were exploited as zero-days. The flaws were abused for an extended period, during which attackers installed custom malware on compromised VPN devices. Organizations using affected SMA1000 models are at risk of unauthorized access and persistent compromise. Because the activity relied on previously unknown weaknesses, detection may be difficult. Users should check for SonicWall patches, review device logs, and verify appliance integrity and configuration.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.